Compliance - Sarbanes-Oxley
|
COSO Components |
Prism Solution |
Control Environment creates the foundation for effective internal control and represents the apex of the corporate governance structure. |
Baseline systems and report on all files and applications that those systems support. This allows I.T. to quickly assess the systems and their criticality in the over-all financial reporting structure. Additionally, application and file monitoring assures individuals are only accessing functions and files that are relevant to their job titles. |
Risk assessment involves the identification and analysis by management of relevant risks to achieve predetermined objectives. Risk assessment may occur at the company level or at the activity level. Assessment of IT risks should include data security, availability and performance analysis. |
Baseline systems, report on any changes that might pose a risk, and restore the original configuration in needed. It also provides performance analysis based on configurable thresholds. |
Control activities are the policies, procedures and practices that are put into place to ensure the business objectives are achieved and risk mitigation strategies are carried out. IT controls include such things as system software control and security controls. |
Automated event consolidation, reporting and archival fulfills the requirement for “an automated, replicable process.” Automatic report creation assures that data found in log entries is accurately presented in report form to key stakeholders in the organization. |
COSO states that information is needed at all levels of an organization. However, the identification, management and communication of relevant information represent an ever-increasing challenge to the IT department. At the activity level, the following may be expected:
|
Simplified summary reports on key events are automatically generated for management review. Reports on specific events, i.e. security breaches, can be automatically generated with the supporting details and distributed to compliance officers. |
Monitoring, which covers the oversight of internal control by management through continuous and point-in-time asssessment processes, is becoming increasingly important to IT management. Improving security can reduce the risk of processing unauthorized transactions and generating inaccurate reports, and can ensure a reduction of the availability of key systems if applications and IT infrastructure components have been compromised. |
Host-based intrusion detection and event correlation are standard features. Additionally, performance monitoring, including CPU, memory and application usage monitoring at use-defined levels can provide early warnings of such things as DOS attaches. Baseline reporting and change detection can assure changes to financial reporting systems are detected. |
Pre-defined SOX Audit-ready Reports: